Embedded Security Hardware Proxy for Virtualized Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized environments, the security-enhanced capabilities of embedded security hardware on computing devices cannot be utilized, as virtualizing this hardware compromises its inherent security and makes it vulnerable to misuse.

Innovation Solution

A proxy architecture that leverages the embedded security hardware of a client computing device within a virtualized environment hosted by a host computing device, using client and host proxies to intercept and relay security requests and responses, allowing the embedded security hardware to be used as if it were part of the host computing device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If embedded security hardware is virtualized to enable access within virtualized environments, then the hardware becomes accessible and usable, but its inherent security is compromised and it becomes vulnerable to misuse

Engineering Contradiction:
ImproveAccessibility of embedded security hardware in virtualized environmentsVSAvoidSecurity integrity of embedded security hardware
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A proxy component is introduced as an intermediary between the virtualized environment and the embedded security hardware. The proxy intercepts security requests from virtual machines, relays them to the physical embedded security hardware, and returns responses to the virtual machines. This mediator approach allows virtual machines to access security capabilities without directly virtualizing the hardware, thereby maintaining security integrity while enabling accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If embedded security hardware is directly accessed by virtual machines, then security capabilities are available to applications, but unauthorized access and misuse become possible

Engineering Contradiction:
ImproveAvailability of security capabilities to applicationsVSAvoidUnauthorized access and misuse risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The proxy serves as a controlled intermediary that all security requests must pass through. It validates requests, manages authentication, and controls access to the embedded security hardware. This ensures that applications can access security capabilities through a standardized interface while the proxy prevents unauthorized access and misuse by enforcing security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The proxy implements feedback mechanisms to monitor and control access to embedded security hardware. It tracks security operations, validates request authenticity, and can revoke or modify access based on security conditions. This feedback loop ensures that security capabilities are available to authorized applications while preventing unauthorized use.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240372838A1Embedded Security Hardware Proxy
Publication Date: 2024.11.07 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US20240372838A1 patent drawing
  • US20240372838A1 patent drawing
  • US20240372838A1 patent drawing

AI summary

A host proxy executable within a virtualized environment hostable by a host computing device for a client device intercepts an embedded security hardware communication request sent by an application executable within the virtualized environment. The host proxy sends the embedded security hardware communication request to a client proxy executable on the client computing device. The client proxy relays the embedded security hardware communication request to embedded security hardware of the client computing device.